The Gentlemen, also known as Gentlemen and The Gentleman, is a financially motivated, Russian-speaking ransomware-as-a-service operation first publicly observed in September 2025. Microsoft tracks its operators as Storm-2697. The operation emerged from Qilin’s affiliate programme and recruits affiliates with a revenue arrangement granting them 90 percent of ransom proceeds. It operates within the Russian-speaking cybercrime ecosystem; direct nation-state tasking or control has not been established. The Gentlemen targets organizations opportunistically across numerous countries, with manufacturing particularly prominent. Other targets include healthcare, government, technology, retail, financial services, energy, education, and defense-related organizations. Its principal extortion model combines sensitive-data theft with encryption and threats to publish stolen information on a leak site. Affiliates obtain initial access through compromised Fortinet FortiGate appliances, exploitation of CVE-2024-55591, stolen or purchased VPN credentials, phishing, and access brokers. Operators maintain shared inventories of compromised appliances and validated credentials for affiliate use. Intrusions involve credential harvesting, internal reconnaissance, privilege escalation, and lateral movement using legitimate administrative utilities, credential-dumping tools, and tunneling software. Stolen information is transferred using tools including Rclone and WinSCP. The operation maintains endpoint-security-disabling capabilities, including the GentleKiller framework. Its Go-based Windows ransomware uses Garble obfuscation, Curve25519 key exchange, and XChaCha20 encryption. It supports credential-assisted self-propagation and deployment through WMI, PowerShell, PsExec, and Group Policy. Attacks disrupt databases, virtual machines, containers, and backup services to increase operational impact and impede recovery. Affiliates retain flexibility in their tooling. One deployed EtherRAT through living-off-the-land techniques, scheduled tasks, and MSI payloads to support persistence, credential theft, privilege escalation, and lateral movement. Another, known as Azazel, abused an AI coding assistant’s Model Context Protocol execution interface as a command-and-control channel and harvested credentials from GitLab pipeline variables and repository history. Azazel also operated the independent LEAKNED leak and data-extortion operation, distinct from the central Gentlemen service.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
65 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
34 malware families attributed to this actor across reporting.
29 additional families tracked in Mallory.
11 CVEs this actor has used in observed campaigns. 11 of them exploited in the wild.
The Gentlemen's operations are heavily associated with compromised Fortinet FortiGate appliances. Researchers observed the group exploiting CVE-2024-55591, using stolen or purchased VPN credentials, and leveraging vulnerable edge devices to gain access to corporate networks.
The Gentlemen’s rumored exploitation of newer vulnerabilities such as CVE-2025-32433 and CVE-2025-33073 likely helped drive its significant increase in attacks from May onward.
The Gentlemen’s rumored exploitation of newer vulnerabilities such as CVE-2025-32433 and CVE-2025-33073 likely helped drive its significant increase in attacks from May onward.
We also observed traces suggesting the exploitation of CVE-2020-1472 (Zerologon) and the vulnerabilities associated with MS17-010.
Privilege Escalation: Immediately scope for and patch the following vulnerabilities known to be exploited: CVE-2025-7771 ( ThrottleStop.sys driver)
6 more CVEs tied to this actor tracked in Mallory.
317 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware-as-a-service operation combining data theft, file encryption, network propagation and endpoint-security disruption. Its Go-based Windows encryptor supports credential- and token-assisted propagation. The operators maintain GentleKiller, an internally developed EDR-disabling framework, alongside externally sourced tools. Publicly reported victims span manufacturing, technology and defence across multiple countries; the article cautions that victim listings do not independently substantiate every operator allegation.
Reportedly conducted a ransomware attack against Aquatech, a US-based water treatment technology company categorized in the report as Energy & Utilities. The breach reportedly occurred on October 6, 2026, at 18:37 UTC and was discovered on October 9, 2026, at 19:27 UTC. The content provides no technical details about the attack.
Reportedly conducted a ransomware attack against AnyTech365, an IT security and remote technical support company. The report dates the breach to October 6, 2026, and discovery to October 9, 2026. It lists the victim's region as GB but describes the company as headquartered in Marbella, Spain; the geographic attribution is inconsistent. No attack mechanics or named ransomware family are provided.
Reportedly conducted a ransomware attack against Greenbrook Engineering, a steel detailing and engineering firm categorized as manufacturing in the incident report. The reported breach occurred on October 6, 2026, and was discovered on October 9, 2026. The report identifies the victim region as GB, although its company description places headquarters in New Jersey and offices in India.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.